SOC-HUB // OPERATIONAL Thu 01 Oct 2026 · UTC
⚠ Live Threats
Rapid7 Cybersecurity · Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)Rapid7 Cybersecurity · Higher education is under siege, and fragmented security is making it harder to respondCISA · CISA Adds One Known Exploited Vulnerability to Catalog  ZDI: Published · ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution VulnerabilityZDI: Published · ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution VulnerabilityICS Advisories · Baicells Nova 430HICS Advisories · Toptech TMS7 and TopHATICS Advisories · Lantronix G520 Series Cellular Gateway
OPERATIONAL // BLUE TEAM

The one stop shop for SOC analysts.

Knowledge base, playbooks, live threat intel, tools and jobs. Everything a defender needs to triage faster and grow from L1 to L3, in one place.

1
KB Articles
0
IR Playbooks
0
Tools
0
Open Roles
// From Team SOC Analysts

Latest analysis

All articles
// Uncategorized
Uncategorized

Hello world!

Welcome to WordPress. This is your first post. Edit or delete it, then start writing!

· 1 min read
// JOIN THE SHIFT

Bookmark SOC-Hub. Start your next shift here.

News, CVEs, playbooks and tradecraft, refreshed continuously and curated for working analysts.

Start reading →